This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ibm First view 2010-04-16
Product Advanced Management Module Last view 2013-08-15
Version 2.50 Type Hardware
Update k  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:h:ibm:advanced_management_module

Activity : Overall

Related : CVE

  Date Alert Description
3.5 2013-08-15 CVE-2013-4007

Cross-site scripting (XSS) vulnerability in adv_sw.php in the Advanced Management Module (AMM) with firmware BBET before BBET64G and BPET before BPET64G for IBM BladeCenter systems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5 2010-07-08 CVE-2010-2656

The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core files via direct requests, as demonstrated by a request for private/sdc.tgz.

4 2010-07-08 CVE-2010-2655

Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allows remote authenticated users to list arbitrary directories and possibly have unspecified other impact via a .. (dot dot) in the DIR parameter.

4.3 2010-07-08 CVE-2010-2654

Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allow remote attackers to inject arbitrary web script or HTML via the (1) INDEX or (2) IPADDR parameter to private/cindefn.php, (3) the domain parameter to private/power_management_policy_options.php, the slot parameter to (4) private/pm_temp.php or (5) private/power_module.php, (6) the WEBINDEX parameter to private/blade_leds.php, or (7) the SLOT parameter to private/ipmi_bladestatus.php.

5 2010-04-16 CVE-2010-1460

The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.

CWE : Common Weakness Enumeration

%idName
40% (2) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
20% (1) CWE-399 Resource Management Errors
20% (1) CWE-264 Permissions, Privileges, and Access Controls
20% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...

Open Source Vulnerability Database (OSVDB)

id Description
66130 IBM BladeCenter Advanced Management Module power_management_policy_options.ph...
66128 IBM BladeCenter Advanced Management Module private/power_module.php URI XSS
66127 IBM BladeCenter Advanced Management Module private/pm_temp.php URI XSS
66126 IBM BladeCenter Advanced Management Module private/blade_leds.php URI XSS
66125 IBM BladeCenter Advanced Management Module private/ipmi_bladestatus.php SLOT ...
66124 IBM BladeCenter Advanced Management Module private/file_management.php DIR Pa...
66123 IBM BladeCenter Advanced Management Module private/sdc.tgz Logging Informatio...
66122 IBM BladeCenter Advanced Management Module private/cindefn.php Multiple Param...
63924 IBM BladeCenter Management Module USB / iSCSI Interrupt Sharing TCP Packet Ha...